RSS Amplifier

Murray’s Newsletter · Aug 12, 2026

Best CISO Events and Cybersecurity Conferences in San Francisco and Silicon Valley in 2026

0
Sign in to vote or save

Murray Newlands · Murray’s Newsletter

CISOs already have too many events.

San Francisco’s cybersecurity calendar includes RSAC Conference, formal CISO summits, vendor programs, conference-week side events, private dinners and specialist roundtables. The shortage is not invitations. It is rooms where security leaders can discuss what failed, what the board asked and which control did not work without spending the evening being sold to.

Large cybersecurity conferences are useful for market breadth; smaller CISO roundtables are better suited to confidential discussion. Executive summits sit between those formats. Private dinners can be excellent when the guest list is credible and sponsor access is controlled.

The first decision is therefore not which event is “best.” It is what kind of security conversation the CISO needs.

A major conference is designed for scale. It brings together vendors, practitioners, researchers, executives and policy voices. It is useful for seeing the market and meeting many people quickly.

A CISO summit concentrates senior security leadership. It usually has a formal agenda, several sessions and more executive-level discussion than a general conference.

A roundtable is smaller and organized around a defined issue such as identity, AI governance, incident response or board reporting.

A private dinner gives the group more time but requires stronger curation. If the attendee mix is wrong, there is nowhere for the conversation to hide.

These are not interchangeable products. A CISO should choose the format before choosing the event name.

RSAC Conference remains the central cybersecurity event in San Francisco. Its value is breadth: security categories, research, vendors, customers, policy questions and an enormous side-event calendar arrive in the city at the same time.

I would use RSAC week to scan the market, schedule focused meetings and attend a small number of carefully selected sessions. I would not expect the main conference floor to provide sustained confidential discussion. That is not what a conference of that scale is built to do.

Conference week also creates a quality-control problem. Many side events borrow the CISO label even when chief security officers are a small minority of the room. Ask who the event is for and what access sponsors receive.

RSAC is probably the better choice when breadth, technical exposure and market intelligence matter. It is the wrong format for disclosing a sensitive control failure.

Gartner and Evanta’s San Francisco CISO Executive Summit is one example of a more formal regional program. The format combines keynotes, boardroom sessions and executive networking. IANS and CISO Network also operate security-leadership programs that can be relevant depending on topic and qualification.

An executive summit can be a good middle ground: more structure than a dinner, more CISO density than a general conference and enough scale to expose leaders to several approaches.

The tradeoff is sponsorship. Cybersecurity events are expensive, and sponsors often make them possible. The question is whether the operator protects the program or allows commercial priorities to shape every conversation.

The dinner format works because many security questions cannot be answered honestly from a stage.

How did the board react to the incident? Which identity program stalled? Who owns agent governance? Where did procurement improve security, and where did it create delay without reducing risk? Those discussions require context and discretion.

Through Open Future Forum, I run private CISO dinners, security roundtables and other senior security events in Silicon Valley. For leaders comparing formats across the market, I also mapped CISO events and cybersecurity conferences in San Francisco.

I would reject any dinner where nearly everyone wants to sell a security product to the CISO. That may be a customer event, but it is not a candid CISO event.

Roundtables are especially useful for AI security, non-human identity, third-party risk, ransomware recovery and board reporting. The best question is narrow enough to invite operational detail.

“What is the future of cybersecurity?” is useless. “Who can authorize an enterprise agent, and what evidence does the CISO require?” is workable.

The host should state whether the session is off the record, how sponsors participate and who qualifies to attend. Without those rules, participants will default to safe answers.

I would choose a roundtable when I wanted several approaches to one decision. I would choose a technical conference session when I needed deeper instruction on a particular system or attack method.

Timing affects value. Early in a planning cycle, a CISO may need market breadth and technical comparison. Before a board meeting, the priority may be risk framing and evidence. After an incident or failed control rollout, a smaller discussion with experienced security leaders can expose assumptions without turning the event into incident consulting.

The program should reflect the maturity of the security function. A newly appointed CISO may benefit from broader leadership sessions and board communication. A mature global function may need narrower work on non-human identity, third-party concentration or recovery design.

I would ask for enough agenda detail to understand the level of discussion. “AI security” could mean threat detection, model protection, enterprise policy, application risk or agent identity. If the operator cannot say which one, the session will probably stay general.

Useful CISO events also respect preparation. A roundtable improves when attendees receive the question beforehand and arrive ready to compare decisions. A dinner improves when the host knows which participants can contribute to the topic. Showing up is not the same as being ready for the room.

CISOs are often told that a private format will create honesty. Privacy helps, but it is not enough. Candor has to be designed with the same discipline as access to a sensitive system.

Participants need to know the boundary: what is off the record, whether comments may be attributed, what sponsors receive and which details should never leave the company. Within that boundary, a CISO can contribute a control pattern, a governance decision or a lesson from a failed rollout without disclosing an exploitable weakness.

This is the security version of give and take. Do not arrive expecting other CISOs to reveal their hardest lessons while offering only approved talking points. Bring a useful pattern, stripped of identifying detail. Ask a question precise enough to earn a precise answer. Reciprocal candor is not oversharing. It is controlled disclosure in service of better judgment.

Security leaders understand that sponsors support events. The problem begins when sponsor access becomes the primary design principle.

A useful sponsor brings data, subject expertise or a relevant operating perspective. A poor sponsor arrangement produces a captive audience. The difference is visible in the agenda: are CISOs asking the questions, or are they being moved through a sequence of demonstrations?

Ask whether the sponsor has speaking time, whether attendee information is shared and whether the session permits criticism of the category. A serious operator should answer directly.

AI has created two security agendas. CISOs must govern enterprise AI use, and they must also assess how attackers and defenders use AI.

Agentic systems add questions about identity, authorization, logging, data access and accountability. A general AI event may not treat those issues with enough depth. A traditional cybersecurity event may focus heavily on threat tooling without addressing business adoption.

The most useful AI-security sessions connect architecture to enterprise control. If the event discusses capability without ownership, it is incomplete for a CISO.

I would build around one primary objective. For market intelligence, spend time at the major conference and pre-book vendor or practitioner meetings. For board and governance questions, choose a CISO summit or roundtable. For candid comparison, add one private dinner with a known guest profile.

I would not attempt to attend everything. Conference-week fatigue lowers the value of every room. A CISO with six evening invitations should decline at least four.

San Francisco is strongest for the major formal program and its side-event density. Palo Alto and Silicon Valley often suit smaller dinners and roundtables involving technology operators. Geography should follow the format.

RSAC Conference is useful for breadth. Gartner/Evanta and other CISO summits provide more formal executive programming. Private dinners and specialist roundtables are better for confidential discussion.

Choose based on the objective: market breadth, technical depth, executive risk, vendor evaluation or confidential operating exchange. No single conference performs all five jobs equally well.

CISOs meet at executive summits, security roundtables, private dinners, RSAC-week gatherings and focused AI-security events across San Francisco and Silicon Valley.

Yes, when the topic is specific, attendees are genuinely senior and sponsor participation is controlled. They are not worthwhile when the guest list is primarily sellers.

A summit offers a broader formal program with multiple sessions. A roundtable is smaller and organized around direct discussion of a defined security problem.

I founded Open Future Forum, so I know the security dinners and roundtables we run more closely than RSAC, Evanta, IANS or the other operators discussed here. Our format is relevant for smaller executive discussion. A major conference is better for breadth, and a formal CISO summit may be better for leaders who want a full programmed day.

The CISO calendar does not need another event selected by logo recognition. It needs a deliberate mix of market breadth, technical depth and protected discussion, with fewer rooms where the security leader is the product.

No posts

Read the original on murraynewlands.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.